Step 7C: Setting IBM Z BCPii Permissions (IBM z14 or later)

There are two levels of BCPii permissions settings, system (processor, CPC) and partition (LPAR) settings. One end of the BCPii communication is the System Automation instance, running in a partition (z/OS LPAR) of a system, and the other end can be any system or partition that is specified as target for the BCPii commands. The Support Elements on both ends must be attached to an IBM processor network, which allows to establish a session between them. The BCPii permission settings on both ends must enable this communication.

System BCPii Permissions

Use the Hardware Management Console (HMC) task System Details of the system and select the tab Security to validate or change the System BCPii Permissions setting. This setting enables the system to accept BCPii query and action commands from all or selected partitions only. This setting affects the targeted system only, not its partitions.

Figure 1. System BCPii Permissions settings

The IBM supplied default is to allow the CPC to receive commands from all partitions of any connected system in your IBM processor network. Note that the SA-BCPii function does not require to change this default!

If you need to change the IBM System BCPii Permissions default, make sure that defined processors in your policy database are enabled to receive BCPii commands from all partitions defined in your policy database, which need to establish SA-BCPii connections to that processor. This is mandatory for all ProcOps ISQET32 and GDPS INTERNAL SA-BCPii connections.

LPAR BCPii Permissions

Use the HMC task Change LPAR Security in section Operational Customization of the system to validate or change the BCPii permission settings on LPAR level to enable receiving incoming query and action commands and to enable sending BCPii commands from the selected partition to other processors and partitions. The IBM supplied default for each partition is to have BCPii send and receive disabled.
Figure 2. LPAR BCPii Permissions settings

If you want to use the SA-BCPii protocol for hardware automation, you must change the IBM default LPAR BCPii permission setting from disabled to either send, receive, or both, depending on the role of the partition in your System Automation policy database or the partition type. For example, CF or SSC partitions cannot issue BCPii commands and do not require BCPii send enabled.

If you have enabled the LPAR to receive BCPii commands, you must also specify whether you allow to receive commands from all partitions in your processor network, or give permission only to selected processors and partitions.

If the BCPii permissions setting includes send, you must check the Cross Partition Authority checkbox, which is displayed next to the BCPii Permissions setting for the selected partition.

It is your responsibility to apply BCPii permissions that allow local and cross CPC BCPii communication that match with your System Automation policy definitions. If you have processors and LPARs defined in your policy database, System Automation cannot determine the current BCPii permission settings, before it tries to access the partition.